News: 1680193506

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Do you use comms software from 3CX? What to do next after biz hit in supply chain attack

(2023/03/30)


Two security firms have found what they believe to be a supply chain attack on communications software maker 3CX – and the vendor's boss is advising users to switch to the progressive web app until the 3CX desktop client is updated.

3CX started as a vendor of PBX software, and evolved to offer voice, video, and collaborationware.

It still sells VoIP systems, and it’s exactly those that appear to have fallen victim to a supply chain attack. The comms company serves a broad variety of industries and [1]lists customers including Mercedes Benz, McDonalds, BMW, Holiday Inn, the NHS, American Express, Coca-Cola and Air France. The biz claims it has more than 12 million daily users, and is or has been used by more than 600,000 organizations.

As many of you have noticed, the 3CX DesktopApp has a malware in it

3CX CEO Nick Galea today [2]confirmed the infection – which users started to clock more than a week ago, we note – and added some details and recommendations for customers.

“As many of you have noticed, the 3CX DesktopApp has a malware in it. It affects the Windows Electron client for customers running update 7. It was reported to us yesterday night and we are working on an update to the DesktopApp which we will release in the coming hours,” said Galea.

[3]

“We strongly recommend using our PWA client instead. It really does 99 percent of the client app and is fully web based and this type of thing can never happen. Only thing you don't have is hotkeys and BLF. But in light of what happened yesterday we are going to address BLF immediately and hotkeys if we can,” said Galea, adding: “So please use PWA for the moment until we release a new build. And consider using PWA instead of Electron.”

[4]

[5]

SentinelOne said it [6]detected unusual activity last week, but behavioral detections prevented trojanized installers from running and triggered a quarantine.

“The trojanized 3CXDesktopApp is the first stage in a multi-stage attack chain that pulls ICO files appended with base64 data from Github and ultimately leads to a 3rd stage infostealer DLL still being analyzed as of the time of writing,” said SentinelOne.

[7]

The Mountain View cybersecurity biz said the DLL appears to “interface with browser data in an attempt to enable future operations as the attackers sift through the mass of infected downstream customers.”

The malware gathers information from Chrome, Edge, Brave and Firefox, including browser history, data from the place table in Firefox and Chrome history tables.

[8]Have we learned anything from SolarWinds supply chain attacks?

[9]Warning on SolarWinds-like supply-chain attacks: 'They're just getting bigger'

[10]Ukrainian cuffed, faces extradition to US for allegedly orchestrating Kaseya ransomware infection

[11]US Treasury, Dept of Commerce hacks linked to SolarWinds IT monitoring software supply-chain attack

The biz issued a takedown request for the repository. [12]Crowdstrike spotted similar activity on both Windows and MacS when it observed “unexpected malicious activity emanating from a legitimate, signed binary, 3CXDesktopApp.”

“The malicious activity includes beaconing to actor-controlled infrastructure, deployment of second-stage payloads, and, in a small number of cases, hands-on-keyboard activity,” summarized the Austin-based security outfit.

Crowdstrike said it suspects the attack is the work of North Korea’s Labyrinth Chollima, a subset of Lazarus. The group primarily conducts espionage operations aimed at US and South Korea militaries.

[13]

On the software maker's [14]forums , customers reported suspicious activity, long lists of files and directories affected, and shell scripts to perform a cleanup.

Curiously enough, those forum posts date back to March 22, with folks warning of an intrusion, yet we're only hearing confirmation now from 3CX.

Supply chain attacks have been a growing threat since 2020’s Solar Wind incident. The 3CX attack is the most prominent since [15]Solar Winds , and the [16]Kaseya crisis that followed.

"This problem is not going away — it's just going to get bigger,” Mandiant's Eric Scales [17]told The Reg earlier this month of supply chain attacks. ®

Get our [18]Tech Resources



[1] https://www.3cx.com/pbx/hosted/

[2] https://www.3cx.com/community/threads/3cx-desktopapp-security-alert.119951/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZCYGhUgr2Q3p6INlN0-3lAAAAFg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZCYGhUgr2Q3p6INlN0-3lAAAAFg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZCYGhUgr2Q3p6INlN0-3lAAAAFg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.sentinelone.com/blog/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZCYGhUgr2Q3p6INlN0-3lAAAAFg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2023/02/05/supply_chain_security_efforts/

[9] https://www.theregister.com/2023/03/03/solarwinds_supplychain_security/

[10] https://www.theregister.com/2021/11/08/revil_ransomware_operators/

[11] https://www.theregister.com/2020/12/14/solarwinds_fireeye_cozybear_us_government/

[12] https://www.crowdstrike.com/blog/crowdstrike-detects-and-prevents-active-intrusion-campaign-targeting-3cxdesktopapp-customers/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZCYGhUgr2Q3p6INlN0-3lAAAAFg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://www.3cx.com/community/threads/threat-alerts-from-sentinelone-for-desktop-update-initiated-from-desktop-client.119806/page-4#post-558867

[15] https://www.theregister.com/2020/12/14/solarwinds_fireeye_cozybear_us_government/

[16] https://www.theregister.com/2021/11/08/revil_ransomware_operators/

[17] https://www.theregister.com/2023/03/03/solarwinds_supplychain_security/

[18] https://whitepapers.theregister.com/



Anonymous Coward

Typically arrogant behaviour by this vendor. It seems they knew about it a fair time before they admitted to it, and partners still have not received any push communication beyond what is on their public site. Do they deserve our business?

Cover up

Anonymous Coward

These shitbags are trying to cover this up. They're downplaying it on social media, they haven't informed their customers (many of whom will have been running a trojan for well over a week!) and they ignored it on their forums for a week before basically replying "take it up with your antivirus company" (you really should see this exchange for yourself, go look at their forum, it's really quite something!).

We use 3CX. We weren't affected by this because we don't use the desktop client. We started looking at alternatives this afternoon!

It's OK

VoiceOfTruth

-> unexpected malicious activity emanating from a legitimate, signed binary

It's legitimate signed malware-infected software.

User was distributing pornography on server; system seized by FBI.